Here is my two cents worth... you must have the users in the local admin group or else the update will not run correctly. We had issues last week where the update was hanging the whole machine and we had to manually add the domain users group to the local admin group. Most of our users are already local admins. Dont forget to run the /silent (silent) and the /F (force) switches when using the sdat410x.exe.
I cant believe that McAfee have left this issue open for so long. It is supposed to help protect attack from viruses but you must meet certain citeria before you can do so. If I figure any way around this then I will post here.